User or device assignment

%3CLINGO-SUB%20id%3D%22lingo-sub-1245842%22%20slang%3D%22en-US%22%3EUser%20or%20device%20assignment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1245842%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20folks%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei%20would%20like%20to%20discuss%20your%20experiences%20with%20user%20or%20device%20profile%20assignment.%3C%2FP%3E%3CP%3EWhat%20specific%20policies%20are%20you%20targeting%20to%20devices%3F%20What%20policies%20are%20you%20targeting%20to%20devices%3F%3C%2FP%3E%3CP%3EOf%20course%20I've%20read%20through%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fconfiguration%2Fdevice-profile-assign%23user-groups-vs-device-groups%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ecorresponding%20docs%3C%2FA%3E.%3C%2FP%3E%3CP%3EAfter%20my%20experiences%20in%20the%20last%20months%20i%20prefer%20assigning%20the%20profiles%20to%20devices.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20I'm%20able%20to%20exclude%20devices.%20(e.g.%20IT-Staff%20has%20one%20corporate%20device%20and%20one%20for%20testing%20purposes)%3C%2FP%3E%3CP%3E-%20The%20workflow%20when%20using%20white%20glove%20seems%20much%20more%20logic.%20(The%20very%20most%20config%20is%20applied%20while%20white%20glove%20process.)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20i%20would%20like%20to%20hear%20your%20experiences.%20What%20are%20advantages%20%2F%20disadvantages%3F%3C%2FP%3E%3CP%3EThank%20you%20in%20advance.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3EWhat%20Assignments%20do%20you%20use%20for%20App%20configuration%20policies%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPatrick%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1245842%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Application%20Management%20(MAM)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1248206%22%20slang%3D%22en-US%22%3ERe%3A%20User%20or%20device%20assignment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1248206%22%20slang%3D%22en-US%22%3EI%20use%20devices%20all%20day%20long%20for%20all%20policies%20in%20Windows%2010%2C%20because%20it%20works%20and%20applies%20faster%20than%20targeting%20the%20users%20so%20you%E2%80%99re%20not%20alone.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1249776%22%20slang%3D%22en-US%22%3ERe%3A%20User%20or%20device%20assignment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1249776%22%20slang%3D%22en-US%22%3EIt%20really%20depends%20on%20your%20environment%20and%20your%20use%20cases%20in%20my%20opinion.%3CBR%20%2F%3E%3CBR%20%2F%3EFor%20Windows%2010%20apps%2C%20I%20mostly%20assign%20them%20to%20users%20(if%20the%20client%20doesn't%20have%20any%20kiosks).%20This%20is%20because%20a%20lot%20of%20apps%20are%20user%2Fdepartment%20specific.%3CBR%20%2F%3E%3CBR%20%2F%3EFor%20configs%20I%20assign%20to%20dynamic%20device%20groups.%20But%20if%20there%20are%20some%20settings%20that%20need%20to%20be%20different%20for%20some%20users%20(for%20example%2C%20the%20finance%20department%20needs%20tighter%20security%20settings)%2C%20assigning%20to%20users%20might%20be%20easier.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20always%20advise%20to%20assess%20your%20environment%20and%20check%20what%20makes%20the%20most%20sense%20for%20you.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1251944%22%20slang%3D%22en-US%22%3ERe%3A%20User%20or%20device%20assignment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1251944%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eso%20there%20is%20not%20definite%20answer%20to%20this%2C%20but%20there%20are%20some%20situations%20where%20it%20really%20makes%20sense%20to%20use%20device%20based%20assignments%20instead%20of%20user%20based%20assignments.%20In%20general%20user%20based%20assignments%20are%20faster%20applied%20as%20they%20can%20be%20evaluated%20instantly%20from%20the%20system.%20The%20user%20is%20always%20there%20and%20can%20have%20the%20relationship%20with%20policies%2Fapps.%20Devices%20pop%20up%20dynamically%20and%20device%20groups%20need%20first%20to%20be%20evaluated%20and%20then%20after%20identifying%20a%20membership%20the%20Intune%20service%20backend%20is%20able%20to%20push%20out%20the%20configs%20or%20apps.%20This%20is%20normally%20not%20a%20problem%20as%20we%20often%20do%20wait%20long%20enough%20to%20allow%20this%20to%20happen.%20Example%3A%20ESP%20waits%20for%20device%20context%20app%20installs%20and%20so%20on.%20So%2C%20enough%20time%20to%20evaluate%20and%20send%20down%20policies%2C%20apps%20etc.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESo%2C%20especially%20for%20configs%20when%20dealing%20with%20exceptions%20like%20shared%20devices%20it%20is%20helpful%20to%20use%20device%20assignments%20as%20you%20are%20able%20then%20to%20exclude%20the%20%22special%22%20cases%20like%20shared%20device%20from%20regular%20baseline%20policies.%20e.g.%20you%20like%20to%20have%20different%20device%20lock%20timeout%20for%20them.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20go%20for%20device%20assignments%20you%20should%20be%20aware%20of%20some%20behavior%2C%20like%20sudden%20logouts%20or%20restarts%2C%20my%20buddy%26nbsp%3B%3CSPAN%3EJ%C3%B6rgen%20Nilsson%20has%20documented%20this%20very%20well%20here%3A%26nbsp%3B%3CSTRONG%3EAutopilot%2C%20ESP%20and%20extra%20login%2Freboots%3C%2FSTRONG%3E%20(%3CA%20href%3D%22https%3A%2F%2Fccmexec.com%2F2020%2F01%2Fautopilot-esp-and-extra-login-reboots%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fccmexec.com%2F2020%2F01%2Fautopilot-esp-and-extra-login-reboots%2F%3C%2FA%3E).%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EApps%20is%20a%20different%20story%2C%20here%20we%20are%20dealing%20with%20company%20portal%20and%20available%20or%20required%20assignments.%20Here%20I%20do%20prefer%20user%20assignments%20if%20possible%2C%20but%20that's%20not%20a%20golden%20rule.%20Also%20for%20required%20deployments%20it%20can%20make%20sense%20to%20use%20device%20assignments.%20I've%20written%20a%20blog%20post%20about%20it%20here%3A%26nbsp%3B%3CSTRONG%3EIntune%20application%20targeting%20for%20Windows%2010%20Win32%20apps%20explained%3C%2FSTRONG%3E%20(%3CA%20href%3D%22https%3A%2F%2Foliverkieselbach.com%2F2020%2F02%2F19%2Fintune-application-targeting-for-windows-10-win32-apps-explained%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Foliverkieselbach.com%2F2020%2F02%2F19%2Fintune-application-targeting-for-windows-10-win32-apps-explained%2F%3C%2FA%3E)%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1290667%22%20slang%3D%22en-US%22%3ERe%3A%20User%20or%20device%20assignment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1290667%22%20slang%3D%22en-US%22%3E%3CP%3E%40Thank%20you%20guys%20for%20your%20ideas%20regarding%20this%20topic.%3C%2FP%3E%3CP%3EI%20already%20thought%20there%20is%20not%20the%20one%20and%20only%20answer.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20others%20feel%20free%20to%20answer%20later%20and%20discuss%20this%20with%20us.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1294918%22%20slang%3D%22en-US%22%3ERe%3A%20User%20or%20device%20assignment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1294918%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E1.%20What%20about%20org-wide%20app%20and%20config%20policies%20(such%20as%20tamper%20protection%20for%20config%20and%20company%20Portal%20for%20app).%3CBR%20%2F%3EDo%20you%20see%20any%20pro%20%2F%20cons%20when%20assigning%20to%20%E2%80%9Call%20users%E2%80%9D%20%2C%20%E2%80%9Call%20devices%E2%80%9C%20or%20%E2%80%9Call%20user%20and%20all%20devices%E2%80%9D%3F%3CBR%20%2F%3E2.%20What%20about%20org-wide%20windows%2010%20compliance%20policy%2C%20in%20the%20GUI%20they%20only%20have%20the%20%E2%80%9Call%20users%E2%80%9D%20option%20(no%20%E2%80%9Call%20devices)%2C%20but%20I%20know%20I%20can%20assign%20compliance%20policy%20to%20devices%20group%20as%20well%2C%20any%20suggestions%20on%20that%20one%20(I%E2%80%99m%20referring%20to%20user%20driven%20only%2C%20no%20kiosk%20or%20self-deployed%20devices)%3F%3CBR%20%2F%3ETnx%2C%3CBR%20%2F%3EGilad.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1432661%22%20slang%3D%22en-US%22%3ERe%3A%20User%20or%20device%20assignment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1432661%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F375902%22%20target%3D%22_blank%22%3E%40giladke%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThese%20are%20exactly%20the%20questions%20i'm%20facing%2C%20too.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

Hi folks,

 

i would like to discuss your experiences with user or device profile assignment.

What specific policies are you targeting to devices? What policies are you targeting to devices?

Of course I've read through the corresponding docs.

After my experiences in the last months i prefer assigning the profiles to devices.

 

- I'm able to exclude devices. (e.g. IT-Staff has one corporate device and one for testing purposes)

- The workflow when using white glove seems much more logic. (The very most config is applied while white glove process.)

 

So i would like to hear your experiences. What are advantages / disadvantages?

Thank you in advance. :)

What Assignments do you use for App configuration policies?

 

Patrick

6 Replies
Highlighted
I use devices all day long for all policies in Windows 10, because it works and applies faster than targeting the users so you’re not alone.
Highlighted
It really depends on your environment and your use cases in my opinion.

For Windows 10 apps, I mostly assign them to users (if the client doesn't have any kiosks). This is because a lot of apps are user/department specific.

For configs I assign to dynamic device groups. But if there are some settings that need to be different for some users (for example, the finance department needs tighter security settings), assigning to users might be easier.

I always advise to assess your environment and check what makes the most sense for you.
Highlighted

Hi,

 

so there is not definite answer to this, but there are some situations where it really makes sense to use device based assignments instead of user based assignments. In general user based assignments are faster applied as they can be evaluated instantly from the system. The user is always there and can have the relationship with policies/apps. Devices pop up dynamically and device groups need first to be evaluated and then after identifying a membership the Intune service backend is able to push out the configs or apps. This is normally not a problem as we often do wait long enough to allow this to happen. Example: ESP waits for device context app installs and so on. So, enough time to evaluate and send down policies, apps etc.

 

So, especially for configs when dealing with exceptions like shared devices it is helpful to use device assignments as you are able then to exclude the "special" cases like shared device from regular baseline policies. e.g. you like to have different device lock timeout for them. 

If you go for device assignments you should be aware of some behavior, like sudden logouts or restarts, my buddy Jörgen Nilsson has documented this very well here: Autopilot, ESP and extra login/reboots (https://ccmexec.com/2020/01/autopilot-esp-and-extra-login-reboots/).

 

Apps is a different story, here we are dealing with company portal and available or required assignments. Here I do prefer user assignments if possible, but that's not a golden rule. Also for required deployments it can make sense to use device assignments. I've written a blog post about it here: Intune application targeting for Windows 10 Win32 apps explained (https://oliverkieselbach.com/2020/02/19/intune-application-targeting-for-windows-10-win32-apps-expla...)

 

best,

Oliver

 

 

Highlighted

@Thank you guys for your ideas regarding this topic.

I already thought there is not the one and only answer. :)

 

Any others feel free to answer later and discuss this with us.

Highlighted
Hi,
1. What about org-wide app and config policies (such as tamper protection for config and company Portal for app).
Do you see any pro / cons when assigning to “all users” , “all devices“ or “all user and all devices”?
2. What about org-wide windows 10 compliance policy, in the GUI they only have the “all users” option (no “all devices), but I know I can assign compliance policy to devices group as well, any suggestions on that one (I’m referring to user driven only, no kiosk or self-deployed devices)?
Tnx,
Gilad.
Highlighted

@giladke 

These are exactly the questions i'm facing, too.